Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.61% | — | RpcbindAI | 22/9/2026 | 25/9/2026 | A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedure Call) statistics in unbounded in-memory lists, leading to persistent memory… | |
| Pendiente de análisis | Media (6.5) | 0.26% | — | RpcbindAIRpcbind RpcinfoAI | 21/7/2026 | 22/7/2026 | A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote RPCBPROC_DUMP reply are written into a fixed-size stack buffer without bounds checking. A user or administrator who runs `rpcinfo -s` against a malicious or compromised… | |
| Pendiente de análisis | Media (6.5) | 0.51% | — | Rpcbind RpcinfoAI | 20/7/2026 | 21/7/2026 | A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server is copied into a fixed-size buffer without sufficient bounds checking. A malicious or compromised rpcbind server could use this flaw to crash the… | |
| Modificada | Alta (7.1) | 0.40% | — | Rpcbind Project Rpcbind | 29/10/2019 | 16/6/2026 | rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr. | |
| Modificada | Alta (7.8) | 0.42% | — | Rpcbind Project Rpcbind | 29/10/2019 | 16/6/2026 | rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is started. | |
| Modificada | Alta (7.5) | 81% | — | Rpcbind Project RpcbindLibtirpc Project LibtirpcNtirpc Project Ntirpc | 4/5/2017 | 17/6/2026 | rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to… | |
| Modificada | Alta (7.5) | 6.4% | — | Rpcbind Project RpcbindCanonical Ubuntu LinuxDebian LinuxOracle Solaris | 1/10/2015 | 17/6/2026 | Use-after-free vulnerability in xprt_set_caller in rpcb_svc_com.c in rpcbind 0.2.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via crafted packets, involving a PMAP_CALLIT code. |